8 ms·
It’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators
by foundry27 2y ago
It’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. Do-Not-Stab, Do-Not-Track, whatever it might be, any sort of “voluntary compliance” is a non-starter in the face of financial pressures
IMO we need to start normalizing being militant about this stuff again, to aggressively and adversarially defend the freedom to use your computer the way you choose to use it
- deleted 2y ago[deleted]
- mpalmer 2y agoTo be extremely pedantic, it's great satire precisely because it mirrors that shift. Owes a lot to the OG, A Modest Proposal.
- thrtythreeforty 2y agoI'm registering my elderly relatives for dmachoice.org, to prevent them from getting junk mail. These clowns create the problem and then have the audacity to charge you to be added to the opt out list. I was really skeptical about the GDPR when it was passed and I am now fully on board for an American version.
- shadowgovt 2y agoI'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.
- blooalien 2y ago> ... "it basically added a cookie banner to every every website I visit" ... Yeah, no. Hostile advertising companies added that cookie banner as a form of "malicious compliance" with the law purely to annoy everyone like a buncha spoil't little brats who didn't get their way, so now they're gonna make everyone suffer... If we get a similar law in the USA, you can expect to see annoyances just like it (and probably worse) on sites hosted here, too.
- thfuran 2y agoNot if we ban third-party ads.
- shadowgovt 2y agoAnd if the regulators didn't predict such compliance they should be replaced with competent actors in their jobs. That was the obvious outcome. What did people predict: site owners leaving money on the table? Who pays for operating the sites then?
- Aeolun 2y agoAll the sites that need advertising like that can just die off and leave the internet a better place.
- shadowgovt 2y agoDid we ever think that would be the end result of all this?
- schmidtleonard 2y agoWhen GDPR was first going through the public circuit I remember reading the proposed laws and being pleasantly surprised to find that they specifically called out and forbade the likely workarounds, including the obnoxious banners we now see everywhere. I would love to know what happened. Did the laws get "revised" to re-open the loophole? Was superseding legislation passed? Did the courts reject it? Are there enforcement issues?
- roenxi 2y agoThat sounds like a legal minefield - I would point out that GDPR-style legislation exists because the legislators don't trust the industry to assess what is reasonable. So the industry would be in a position where: 1) They aren't trusted to be reasonable about user consent. 2) They are only to take action when they judge it is reasonable to check user consent. It'd probably be a very rocky process to nail down what those words like "loophole" and "workaround" mean as the advertisers start abusing prescribed no-banner situations.
- dcsommer 2y agoePD in 2002 mandated cookie banners well before GDPR in 2018. But yes, point taken that well intentioned regulation can be poorly implemented and have negative repercussions.
- lolc 2y agoI know of no regulation that mandated cookie banners. I just know a lot of sites who chose to use banners because the operators are somewhere between weasely and malicous.
- adra 2y agoClearly you don't have a browser plugin that simply opts out of all cookie banners. Ultimately, the webs ites have a financial interest in malicious compliance, so you either work within the system as given or throw your hands in the air and let every and all sites rape your data.
- shadowgovt 2y agoYes, the second one. I don't really care; it's not "my" data. It's data about me. When I walk down the street and sometime sees me go by, those aren't my photons they caught. By analogy, same with my browsing history.
- rockskon 2y agoYou are the culmination of your life's experiences. Going by your definition, one could infer an individual has zero intrinsic ownership of any non-health data. Which I categorically object to.
- Aloisius 2y agoYou have ownership over your own memories and records. Other people also own their own memories and records - some of which may be about you. At least, this is how it was for most of human history. Now some people think they should be able to demand everyone destroy records about them. If it was possible, no doubt they'd also demand people destroy any memories about them as well.
- rockskon 2y agoThat's not how it's been for the bulk of modern history. What absolute absurdity. It's an ancap mentality taken to the notion of privacy.
- Zak 2y agoIt is, however worth at least considering restrictions on continuously following a person in public places and reporting all their observed activities to a third party. Of course there are practical limitations on that kind of physical surveillance. It's expensive, tends to attract attention, and even nation states can only do it to a few people at a time. Information technology allows it to scale to almost everyone, almost all the time, for a small fraction of a corporate budget. Perhaps it's worth at least considering restrictions on that.
- Aeolun 2y agoThe cookie banner is only there because the website in question uses non-functional cookies (e.g. targeted advertising)
- Aloisius 2y agoIt's gotten entirely out of hand. Most EU national government websites have cookie banners. Even the European Commission website has a cookie banner! This should have been implemented at the browser level. Let the browser generate a nice consistent UI to nag EU users when visiting websites about accepting cookies and let the rest of us opt out.
- almostnormal 2y agoThe standard for cookies should be updated with a way to include or retrieve a description of each cookie separately. Then, require sites to provide that description, and let users choose per cookie in the browser.
- Sander_Marechal 2y agoThat's nonsense. It's not about the cookies, it's about the data collection. You can use cookies without having to use a cookie banner by simply not gathering data you don't need. And if you do gather that data without using cookies you still need to ask for consent.
- dcow 2y agoI can tell you, with absolute certainty, that nobody knows how to implement the law or what it even means, legislators, lawyers, engineers alike. There was a good somewhere and now we're in hell.
- phatskat 2y agoAs someone who was helping to implement GDPR for clients when it took effect, it was a nightmare. We didn’t know exactly what to do, or when, or where, or to whom. The easiest solution for a lot of the implantations was “do the most so we don’t miss something, and pull back bits as we know more”.
- samtheprogram 2y agoI click no to all of them, but it would be really nice if the Do-Not-Track header essentially let you pick in advance — for you (0) or for me (1)
- rurban 2y agoNot just "really nice". It must be mandatory to respect it.
- d3VwsX 2y agoThe only hope I still have is for some kind of fully local LLM-driven "agent" browser that does the browsing for me, navigating search engines, cookie banners and showing me what it found, nothing else. Unfortunately entire businesses are built around preventing people from using bots, for obvious reasons, so the only obvious way forward to make browsing the web a better experience will also mean ending up on the wrong side of that battle.
- mola 2y agoNo,.all the companies running the sites chose to add a cookie banner. And you choose to keep going there
- shadowgovt 2y agoYes, and my life world be more convenient if this banner would go away or I could declare a universal preference. I miss the old Internet where nobody cared about their privacy.
- williamdclt 2y agonobody cared about their privacy because there was no widespread systematic effort to invade it. I don't care about my privacy in the street despite it being public because there's no-one following my every step taking note of where I go, how fast, what music I'm listening to, what I'm looking at... (although the astute reader will argue that this is less and less true, there's more and more tech tracking our activity in real life too)
- badgersnake 2y agoCookie banners are malicious compliance and the failure to do anything about them is indicative as to how much the EU cares about privacy vs how much they want to be seen to be caring about privacy.
- pjc50 2y agoThe problem is GDPR isn't prescriptive enough. That makes it ripe for "technically correct but really annoying" solutions. It also failed to actually ban ad tracking.
- moritonal 2y agoKey to note that the cookie banner fiasco wasn't GDPR, it was a separate policy that should be changed.
- account42 2y agoGood job rewarding those companies for adding the nag screen. I'm sure that will get them to stop.
- shadowgovt 2y agoIf by 'companies' you mean https://commission.europa.eu/ https://commission.europa.eu/ then sure.
- shadowgovt 2y agoOn the internet, it started as the user's responsibility. For netizens, the idea that the use should be able to opt out of logs about their interaction with the service the operator owns is novel (because they always had the option of not using the service if they found the pattern distasteful).
- blooalien 2y agoThere's a bit of a difference between normal logging of access to services to protect your devices / network (and to understand your users' access to your services), and using every nasty trick in the book to build extensive detailed profiles of everyone's browsing footprint across the entire web, often without their knowledge or consent (hence the laws, because it's the only way to convince some folks to not do bad things). The first should be expected behavior, whereas the second should be considered unacceptable and abusive, but has somehow been "normalized" in modern society.
- shadowgovt 2y agoIt's a difference of degree, not kind, which is how it became normalized.
- hedora 2y agoThe internet started with decentralized protocols like NNTP, so you could just choose a different news server if the one you were using started tracking + selling your download logs. Centralizing the serving of third party (or even first party) content is already way outside the original norms of the internet. Heck, back in the day, HTTP caching would be enough to block tracking. (No javascript, and only the ISP sees which users pulled the document from cache.)
- Aloisius 2y agoThe internet/arpanet started largely with centralized protocols like various file transfer protocols, telnet, finger, various networked filesystem protocols, network printer protocols, network graphics protocols, echo, QOTD, etc.
- wkat4242 2y agoYeah and the fuss about it being enabled by default is not really relevant. In the EU tracking must be opt-in anyway. So this is expected behaviour. However the EU dropped the ball by not making it mandatory to respect this flag. If they had we wouldn't have had the huge cookiewall mess we have now.
- Deukhoofd 2y agoThe annoying thing is that they have regulations in trilogue that would actually make the DNT header obligatory to follow, the ePrivacy Regulation. That was supposed to drop alongside GDPR, but has instead been delayed for 6 years now. It's apparently supposed to be finally finalized somewhere in 2024, so I hope to see it sometime soon.
- wkat4242 2y agoOh that's good news, that would be great, then I can just set that flag and will never have to bother with cookie banners again <3
- IgorPartola 2y agoI wonder if there is some way to DoS the tracking services by basically accepting third party cookies but then immediately discarding them so every page load generates a new cookie and presumably state stored on the other end to match it. Or are these tracking cookies typically self-contained so that no state is stored server-side?
- tliltocatl 2y agoGiven that web industry uses no-server-state for *authentication* (with all the issues it implies), i would expect tracking also be no-server-state.
- rixed 2y agoIsn't that the reason cookies were invented in the first place? To keep servers stateless?
- afiori 2y agoIf the server can recognize you then it is not stateless, cookies make http stateless
- aaronbrethorst 2y agoBest time to do that would've been 19 days ago, but here we are. Buckle up.
- photonthug 2y ago> aggressively and adversarially defend the freedom to use your computer the way you choose to use it Sadly even if you’re inclined to do this, it’s always a war of attrition, and corporations seem to realize they can just up the cost of your resistance in terms of time/frustration, and that’s enough for them to win in the long term. The history and trajectory of platforms, from browsers to AppStore’s to SaaS-all-the-things, is just tragic, with the amount of user control on a downward slide at each stage. The big question now is whether / how / to what extent AI is going to be corporate or democratized, but it’s hard to be optimistic. Or, you know, if Clicking do-not-stab for 60 more years sounds like it sucks, you can try to become a shepherd or something. Works great for ~10 years, and then you can’t use cars, dishwashers or light switches without clicking do-not-stab, at which point they finally win and you say, you know what? I should be grateful they asked before they stabbed me, I practically owe it to them anyway, and I can’t wait to see all the love/cash rolling in after I’m a big shot shepherd influencer. Like and subscribe y’all and as always, hail corporate
- ratmeadow 2y agoWorth noting the times where you have the choice to engage or not with a company with bad practices. Make it unprofitable for them to provide horrible service. Particularly applicable to tech, because most of it is useless rubbish we don't really need anyway!
- fsflover 2y agoReminds me of Graphene OS, which forces you to directly give money to Google to buy a Pixel, if you care about privacy and security.
- travisgriggs 2y agoIs this a case where monopoly actually benefits the cause? The last great uprising in the public interest, imo, was Microsoft against the open source movements at the turn of the century. It was a heady time to be involved in software. I miss it frankly. But perhaps it really only succeeded, because that Microsoft was like the Boeing of today, a company where Pournelles second type (the institutionalists) had taken over and was just riding out the momentum, allowing the upstart unfunded open source hippies to actually have success.
- tbrownaw 2y ago> larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. If anything the shift is going the other way, with some of the more busy-body jurisdictions trying to take things that are properly enforced by the user's user-agent and instead making them officially the responsibility of the other party.
- klabb3 2y ago> IMO we need to start normalizing being militant about this stuff again, to aggressively and adversarially defend the freedom to use your computer the way you choose to use it Yes. As a millennial the times of civil disobedience was better. Not only did we get a better internet for consumers, but better companies were rewarded and won. Rose tinted glasses? Possibly, but there’s another reason for disobedience: the other side does it, and they do it just for money. Concretely, is there something like Adblock that can be done for cookies? I don’t think blocking is as effective as poisoned data though. They ask for data, they should get it. If you don’t get consent, poisoned data is merely malicious compliance. It could even be standardized as an extension to DNT: “if asking for consent after a DNT header, a UA MAY generate arbitrary synthetic data”.
- cjs_ac 2y ago> Concretely, is there something like Adblock that can be done for cookies? I use a combination of two browser extensions: Cookie AutoDelete[0] and I don't care about cookies[1]. The second hides any GDPR 'compliance' popup; the first deletes any cookies set by a website when you close the last tab with it open. Both extensions have whitelist functionality. [0] https://github.com/Cookie-AutoDelete/Cookie-AutoDelete https://github.com/Cookie-AutoDelete/Cookie-AutoDelete [1] https://www.i-dont-care-about-cookies.eu/ https://www.i-dont-care-about-cookies.eu/
- Tarq0n 2y agoGDPR compliance isn't about cookies, it's about processing personal data. You can be tracked without cookies, so ignore these at your own peril.
- tremon 2y agoGDPR compliance also requires explicit opt-in, so ignoring those popups has the same effect as refusing to be tracked. YMMV of course, but I don't see why ignoring cookie banners should lead to worse results than laboriously denying to be auctioned off.
- 2y ago
- pims 2y agoIt's amusing to see this message heavily upvoted on HN when most mentions of Firefox here are welcomed with an avalanche of perfect solution fallacies. I'm dubious about people becoming militant about this when the software engineering industry gave Chrome a red carpet by using it and installing it on their relatives' computers while knowing very well it's adware and when switching to the alternative is incredibly cheap.
- latexr 2y ago> It's amusing to see this message heavily upvoted on HN when most mentions of Firefox here are welcomed with an avalanche of perfect solution fallacies. HN is not a hive mind. There are people here who love Firefox, people who despite it, and everyone in between. It’s tiring to always be reading your type of comment, as if everyone is a hypocrite. Maybe, just maybe, the people making those contradictory comments are not the same individuals. And it’s not like Mozilla is free from controversies, including several of betraying user trust. If every major browser maker is going to break your trust and sell your data, I can see why people choose their poison based on other factors. I use neither Firefox nor Chrome. Is Safari any better? Or Brave? In some areas yes, in others no. I don’t think there’s a single browser vendor which gets it unambiguously right.
- pims 2y ago> HN is not a hive mind. There are people here who love Firefox, people who despite it, and everyone in between. It’s tiring to always be reading your type of comment, as if everyone is a hypocrite. Maybe, just maybe, the people making those contradictory comments are not the same individuals. I didn't mean to say that all of HN despises Firefox, but simply that it very often brings negative sentiments, so seeing the comment I was responding to so high up in the thread made me react. It was also a kind reminder that militating is as simple as using an alternative to Chrome. > And it’s not like Mozilla is free from controversies, including several of betraying user trust. If every major browser maker is going to break your trust and sell your data, I can see why people choose their poison based on other factors. > I use neither Firefox nor Chrome. Is Safari any better? Or Brave? In some areas yes, in others no. I don’t think there’s a single browser vendor which gets it unambiguously right. And you're making my point about the perfect solution fallacy as well! Of course Firefox isn't perfect and has screwed up on several occasions, does that mean it's comparable to a piece of software that sends every single bit of information it can gather to its parent ad company?